\relax 
\citation{cover1967nearest}
\citation{bicego2016weighted}
\citation{Zhong:2017:IKC:3055635.3056604}
\citation{goodfellow2014explaining}
\citation{wang2017analyzing}
\citation{lin2011parameter}
\@writefile{toc}{\contentsline {section}{\numberline {I}Introduction}{1}}
\newlabel{sec:introduction}{{I}{1}}
\citation{gordo2016deep}
\citation{simard1998transformation}
\citation{cover1967nearest}
\citation{cover1967nearest}
\citation{chaudhuri2014rates}
\citation{Zhong:2017:IKC:3055635.3056604}
\citation{bicego2016weighted}
\citation{zhang2017efficient}
\citation{lin2011parameter}
\citation{guyon2003introduction}
\citation{draszawka2015improving}
\citation{pawlovsky2014method}
\citation{shi2011improved}
\citation{el2006study}
\citation{goodfellow2014explaining}
\citation{wang2017analyzing}
\@writefile{toc}{\contentsline {section}{\numberline {II}Related Work}{2}}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {II-A}}Works on Nearest Neighbors}{2}}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {II-B}}Works on Adversarial Samples}{2}}
\citation{zugner2018adversarial}
\citation{wang2017analyzing}
\citation{szegedy2013intriguing}
\citation{byrd1995limited}
\citation{tabacof2016exploring}
\citation{goodfellow2014explaining}
\citation{carrara2017detecting}
\@writefile{toc}{\contentsline {section}{\numberline {III}Background And Problem Statement}{3}}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {III-A}}KNN Basic Theory}{3}}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {III-B}}Attack model for adversarial samples}{3}}
\newlabel{L-BFGS}{{3}{3}}
\citation{zhang2018nearest}
\citation{gao2018self}
\citation{karampatziakis2013discriminative}
\citation{sani2017learning}
\citation{chandrasekhar2016practical}
\citation{carrara2017detecting}
\citation{sugiyama2007dimensionality}
\newlabel{FGSM}{{4}{4}}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {III-C}}Deep feature selection}{4}}
\@writefile{lof}{\contentsline {figure}{\numberline {1}{\ignorespaces Framework of Adversarial Samples Detections\relax }}{4}}
\providecommand*\caption@xref[2]{\@setref\relax\@undefined{#1}}
\newlabel{deepfeature}{{1}{4}}
\@writefile{toc}{\contentsline {section}{\numberline {IV}improved robust classifier Methodology}{4}}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {IV-A}}Deep feature based feature represention and reduction}{4}}
\citation{liu2011k}
\citation{sermanet2013overfeat}
\newlabel{dis-metric}{{5}{5}}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {IV-B}}Nearest space classifier - all samples considered k nearest neighbors similarity search}{5}}
\newlabel{distance_metric}{{6}{5}}
\newlabel{distance_metric_withoutoverfit}{{7}{5}}
\newlabel{probability}{{8}{5}}
\citation{simard1998transformation}
\citation{carrara2017detecting}
\@writefile{toc}{\contentsline {subsection}{\numberline {\unhbox \voidb@x \hbox {IV-C}}Adversarial samples dection}{6}}
\newlabel{matrix}{{9}{6}}
\@writefile{lot}{\contentsline {table}{\numberline {1}{\ignorespaces Classification Accuracy under Adv. Perturbations\relax }}{6}}
\newlabel{tabel_1}{{1}{6}}
\@writefile{toc}{\contentsline {section}{\numberline {V}Performance Evalution}{6}}
\@writefile{lot}{\contentsline {table}{\numberline {2}{\ignorespaces Classificaton Prediction Performance Comparison.\relax }}{7}}
\newlabel{table_2}{{2}{7}}
\@writefile{lof}{\contentsline {figure}{\numberline {2}{\ignorespaces The Ratio of TP under Different Thresholds\relax }}{7}}
\newlabel{Differrnt dataset}{{2}{7}}
\@writefile{lof}{\contentsline {figure}{\numberline {3}{\ignorespaces TP and FP Rates with Different Threhold on Confidence Score\relax }}{7}}
\newlabel{TF Rate}{{3}{7}}
\newlabel{density distribution1}{{4(a)}{8}}
\newlabel{sub@density distribution1}{{(a)}{8}}
\newlabel{density distribution2}{{4(b)}{8}}
\newlabel{sub@density distribution2}{{(b)}{8}}
\newlabel{density distribution3}{{4(c)}{8}}
\newlabel{sub@density distribution3}{{(c)}{8}}
\@writefile{lof}{\contentsline {figure}{\numberline {4}{\ignorespaces Scores Distribution for the Adversarial and Clean Samples with the AK-NN under Different Data Sets.\relax }}{8}}
\@writefile{lof}{\contentsline {subfigure}{\numberline{(a)}{\ignorespaces {}}}{8}}
\@writefile{lof}{\contentsline {subfigure}{\numberline{(b)}{\ignorespaces {}}}{8}}
\@writefile{lof}{\contentsline {subfigure}{\numberline{(c)}{\ignorespaces {}}}{8}}
\newlabel{density distribution}{{4}{8}}
\@writefile{toc}{\contentsline {section}{\numberline {VI}Discussion And Conclusion}{8}}
\bibstyle{unsrt}
\bibdata{ref}
\bibcite{cover1967nearest}{1}
\bibcite{bicego2016weighted}{2}
\bibcite{Zhong:2017:IKC:3055635.3056604}{3}
\bibcite{goodfellow2014explaining}{4}
\bibcite{wang2017analyzing}{5}
\bibcite{lin2011parameter}{6}
\bibcite{gordo2016deep}{7}
\bibcite{simard1998transformation}{8}
\bibcite{chaudhuri2014rates}{9}
\bibcite{zhang2017efficient}{10}
\bibcite{guyon2003introduction}{11}
\bibcite{draszawka2015improving}{12}
\bibcite{pawlovsky2014method}{13}
\bibcite{shi2011improved}{14}
\bibcite{el2006study}{15}
\bibcite{zugner2018adversarial}{16}
\bibcite{szegedy2013intriguing}{17}
\bibcite{byrd1995limited}{18}
\bibcite{tabacof2016exploring}{19}
\bibcite{carrara2017detecting}{20}
\bibcite{zhang2018nearest}{21}
\bibcite{gao2018self}{22}
\bibcite{karampatziakis2013discriminative}{23}
\bibcite{sani2017learning}{24}
\bibcite{chandrasekhar2016practical}{25}
\bibcite{sugiyama2007dimensionality}{26}
\bibcite{liu2011k}{27}
\bibcite{sermanet2013overfeat}{28}
\@writefile{toc}{\contentsline {section}{REFERENCES}{9}}
\@writefile{toc}{\contentsline {subsection}{Yi Ren}{10}}
\@writefile{toc}{\contentsline {subsection}{Xia Xie}{10}}
\@writefile{toc}{\contentsline {subsection}{Hai Jin}{10}}
\@writefile{toc}{\contentsline {subsection}{Hanhua Chen}{10}}
